All skills
aws avatar

/aws-containers

@df5d2e8

Builds and deploys containerized workloads on Elastic Kubernetes Service (EKS), Elastic Container Service (ECS), Fargate, and ECR (Elastic Container Registry). Covers general EKS knowledge, Karpenter, AWS Load Balancer Controller and leveraging various open source Kubernetes projects with EKS. Covers general ECS knowledge, task definitions, Fargate services, ECS Exec, ECS Express Mode and ECS Managed Instances. Covers general Elastic Beanstalk knowledge, Elastic Beanstalk configuration and platforms supported by Elastic Beanstalk. Covers general ECR knowledge, ECR repository setup and lifecycle policies. Includes recommending, enabling, and reading Amazon ECS Action Logs to troubleshoot control-plane failures (deployment rollback/circuit-breaker, task placement, scaling, task replacement). Applies when deploying, debugging, or optimizing containers on AWS. Should be used instead of relying on internal knowledge for these services.

Use this Skill: https://skilld.dev/gh/aws/agent-toolkit-for-aws/aws-containers

This session only. Nothing lands on disk.

referencesbeanstalk-configuration.md

≈1.4k tokens on demand. Your agent reads this file only when SKILL.md points to it.

Elastic Beanstalk - Configuration and Customization

Configuration Hierarchy

Option settings are applied in this order (later overrides earlier):

  1. Platform defaults (managed by AWS)
  2. Saved configurations (reusable templates)
  3. .ebextensions/*.config files (in source bundle)
  4. Environment properties (set via console/CLI/API)

Platform hooks (/platform/hooks/prebuild/, predeploy/, postdeploy/) run shell scripts during deployment lifecycle but do not set option settings. They are the preferred customization mechanism on AL2023 for non-option-setting tasks. Use .ebextensions/ for option settings and resource declarations.

See Configuration options precedence for full details.

Option Settings Format

When using --option-settings with the AWS CLI, pass a JSON array:

[
  {
    "Namespace": "aws:autoscaling:launchconfiguration",
    "OptionName": "InstanceType",
    "Value": "t3.small"
  },
  {
    "Namespace": "aws:autoscaling:launchconfiguration",
    "OptionName": "IamInstanceProfile",
    "Value": "my-app-instance-profile"
  },
  {
    "Namespace": "aws:elasticbeanstalk:environment",
    "OptionName": "LoadBalancerType",
    "Value": "application"
  },
  {
    "Namespace": "aws:elasticbeanstalk:environment:process:default",
    "OptionName": "HealthCheckPath",
    "Value": "/health"
  }
]

See Configuration options namespaces for the full list of namespaces and option names.

Key Patterns

Run commands on deploy

container_commands:
  01_migrate:
    command: "python manage.py migrate --noinput"
    leader_only: true

Use leader_only: true for commands that should run on only one instance (database migrations, cache warmup).

Procfile

Define the process to run. EB uses this instead of platform defaults:

web: gunicorn myapp.wsgi --bind 0.0.0.0:5000

For worker environments, the Procfile defines the HTTP server that receives SQS daemon POST requests (not a queue consumer like Celery — EB Workers use HTTP, not a message broker SDK).

Environment Properties and Secrets

Non-secret config uses aws:elasticbeanstalk:application:environment. For secrets, use the native secrets integration which injects Secrets Manager values as environment variables without application-side SDK calls:

option_settings:
  aws:elasticbeanstalk:application:environment:
    APP_ENV: staging
  aws:elasticbeanstalk:application:environmentsecrets:
    DB_PASSWORD: arn:aws:secretsmanager:us-east-1:111122223333:secret:myapp/db

The environmentsecrets namespace requires a minimum platform version for compatibility, see the relevant documentation for details.

Never hardcode secrets in .ebextensions/ or source code. Provision databases and secrets as separate resources — not coupled to the EB environment lifecycle.

See Environment secrets for supported secret sources.

Deployment Policies

Policy Use Case Downtime
All at once Dev environments Yes
Rolling Production, cost-sensitive No (partial capacity)
Rolling with additional batch Production, full capacity No
Immutable Production, safest No
Traffic splitting Canary testing No

Default: All at once for dev, Rolling with additional batch for production.

See Deployment policies and settings for configuration details.

Reverse Proxy Port

AL2023 platforms use nginx as a reverse proxy, forwarding to port 5000 by default. If the application listens on a different port, set the PORT environment property to match. Mismatched ports result in 502 Bad Gateway from nginx.

Health Check

Always configure a dedicated health check endpoint. Do not use / if it performs database queries or heavy computation.

The agent should verify that the application exposes a health endpoint (default: /health). If no health route exists, scaffold a minimal one that returns 200 OK. The ALB health check will fail without this, causing deployment to roll back.

See Health check setting for ALB health check configuration.

Heroku Migration

When migrating from Heroku/Render/Railway, audit for these patterns:

  • DATABASE_URL → Provision RDS/Aurora separately, pass via environment secrets
  • REDIS_URL → Provision ElastiCache, pass endpoint via environment properties
  • Add-on env vars (e.g., SENDGRID_API_KEY) → Store in Secrets Manager
  • PORT → See Reverse Proxy Port section above; set if app doesn't use 5000
  • Procfile → Works as-is (same format)
  • Explicit AWS credentials → Remove; use IAM instance profile instead

Source: SKILL.md on GitHub

No alertstoday3 checks · Risk SAFE
  • Gen Agent Trust Hubtoday

    This skill provides technical guidance for AWS container services and appears to follow security best practices, such as recommending the use of Secrets Manager and least-privilege IAM roles. All external resources originate from official or well-known sources, and no security issues were detected.

  • Sockettoday

    No alerts

  • Snyktoday

    Risk: LOW · No issues

Signed by skilld at df5d2e8. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub yesterday.

Activeupdated 3 weeks ago
What it can do
Reads files
metadata
{
  "version": "2"
}
All 1 allowed tools
Read

README badge

README badge for aws/agent-toolkit-for-aws/aws-containers